- Sources: nesbitt.io writeup, HN 48991882
- Summary: A 2026-07-21 writeup explains git's
--end-of-options flag (added in git 2.24.0 in 2019) and the argument-injection class it defends against (CWE-88). Because git overloaded -- to separate revisions from pathspecs, a revision or ref argument that begins with a dash can be parsed as an option even when a wrapper calls exec directly with no shell involved, so an input like --upload-pack=<cmd> becomes a code-execution primitive. The author surveys 19 package managers that fork the git binary for dependency fetches and reports only Go's toolchain consistently passes --end-of-options, with most others adding -- or input validation reactively after CVEs rather than proactively. - Why it matters: Package managers that fork git on untrusted refs are a broad supply-chain surface, and the post names a concrete proactive mitigation that most tools still do not apply.
send feedback on this story